Legal Privacy Policy
Privacy Policy
Document version 3
Effective date: 19 September 2026
Last updated: 19 September 2026
Document version: 3.0
Operator: Next Shopper IT Solutions LLC (“NextShopper”, “Company”, “we”, “us”, or “our”)
Trading as: NextShopper · https://nextshopper.com.bd
Registered office: 7901 4TH ST N STE 300, ST. PETERSBURG, FL 33702, United States
Customer contact: [email protected]
These policies form part of the binding contract between you and NextShopper when you create an account, place an order, pay an invoice, or use our Services. Browse all legal documents at /legal.
Privacy Policy
Please read this Privacy Policy carefully. It explains how NextShopper collects, uses, stores, shares, and protects personal data when you visit https://nextshopper.com.bd, use our client portal, complete checkout, contact support, or purchase Services (domains, hosting, email, SSL, and related digital products).
This Policy is designed to meet transparency expectations under Bangladesh Digital Commerce Operational Guidelines (what data is collected, where it is stored, how it is processed, and future uses, with affirmative consent for purchase-related personal data) and to follow widely recognised privacy practices used by leading hosting and domain providers.
Related documents: Cookie Policy · Terms of Service · Complaints Policy
1. Who we are (data controller)
Controller: Next Shopper IT Solutions LLC
Address: 7901 4TH ST N STE 300, ST. PETERSBURG, FL 33702, USA
Privacy contact: [email protected] (subject line: “Privacy Request”)
Website: https://nextshopper.com.bd
2. Scope
This Policy applies to personal data we process as a controller for our storefront and customer relationship. If you host websites or email for your own end users on our infrastructure, you are typically the controller for that end-user data, and we act as a processor/service provider to the extent we process it solely to provide hosting. You must have a lawful basis to upload or process such end-user data.
3. Personal data we collect
3.1 Account and profile data
Name, email address, phone number, password hash, preferred locale, preferred currency, country, organisation name, tax identification number (if provided), and account status.
3.2 Billing and transaction data
Billing address, invoice and order history, payment method type (for example card brand last four via gateway, PayPal account reference, bKash wallet reference, bank transfer reference), amounts, currency, tax lines, refunds, chargebacks, and gateway transaction identifiers. We do not store full card PAN or CVV on our servers.
3.3 Domain registration data
Registrant, administrative, technical, and billing contact fields required by registrar/registry policy (which may include organisation, postal address, email, and telephone). Accuracy is mandatory.
3.4 Technical and security data
IP address, user agent, device/browser type, timestamps, authentication events, session identifiers, approximate geolocation derived from IP, abuse and fraud signals, and server/application logs.
3.5 Support and complaints data
Messages, attachments, ticket metadata, call notes (if any), and complaint records.
3.6 Marketing preferences
Email opt-in status and campaign interaction data, only where consent or another lawful basis applies.
3.7 Cookies and similar technologies
Described in the Cookie Policy.
3.8 Data from third parties
Payment gateways (payment status), upstream registrar (domain status), hosting panels (provisioning status), and publicly available RDAP/WHOIS where relevant to support or abuse handling.
4. Why we process data (purposes) and legal bases
| Purpose | Examples | Typical legal basis |
|---|---|---|
| Contract performance | Create Account, take Orders, provision Services, renewals, support | Contract |
| Payments and invoicing | Charge fees, issue invoices, process refunds | Contract / legal obligation |
| Domain compliance | Submit registration data, accuracy verification, RDAP/WHOIS obligations | Contract / legal obligation |
| Security and fraud prevention | Login protection, abuse detection, chargeback prevention | Legitimate interests / contract |
| Legal compliance | Tax records, responding to lawful requests, consumer complaints | Legal obligation |
| Service communications | Order confirmations, renewal notices, security alerts | Contract |
| Product improvement | Aggregated analytics, reliability metrics | Legitimate interests / consent where required |
| Marketing | Offers and newsletters | Consent (or soft opt-in where lawful) |
You may withdraw consent where processing is consent-based without affecting the lawfulness of prior processing. Service communications required to perform the contract are not optional.
5. Where data is stored and international transfers
5.1 Data may be stored on application servers, databases, backups, logging systems, and processor systems in the United States, Bangladesh, and other countries where our providers operate.
5.2 Because our legal entity is in Florida and many processors are global, personal data may be transferred across borders. We use contractual and technical safeguards appropriate to the risk (including HTTPS in transit, access controls, and processor agreements where applicable).
5.3 By using the Services, you understand that your data may be processed in countries that may not provide the same legal protections as your home country, subject to the safeguards above and mandatory law.
6. Who we share data with
We share personal data only as needed with:
- Payment processors: Stripe, PayPal, bKash, and banks for payment, refund, and fraud screening.
- Upstream domain registrar and registries: to register and manage domains.
- Hosting, email, DNS, and SSL providers / CAs: to provision and operate Services.
- Transactional messaging vendors: email/SMS delivery of service notices.
- Professional advisers: lawyers, accountants, auditors under confidentiality.
- Authorities and complainants: when required by law, court order, ICANN/registrar process, UDRP/URS, or to protect rights, safety, and security.
- Business successors: in a merger, acquisition, or asset sale, with notice where required.
We do not sell personal information. We do not allow third parties to use personal data for their own unrelated marketing.
7. WHOIS / RDAP and registration data disclosure
Domain registration data may be published or disclosed through WHOIS/RDAP or provided to parties with a legitimate basis under ICANN Registration Data Policy, registrar policy, registry rules, or applicable law. If you purchase privacy/proxy services where offered, public display may be masked subject to that service’s terms; underlying data must still be accurate and available to the registrar as required.
8. Retention
| Category | Retention guide |
|---|---|
| Active Account and Service data | While the relationship is active |
| Invoices, tax, and transaction records | Typically six (6) years (aligned with common commercial record-keeping expectations in Bangladesh and accounting needs), or longer if required |
| Support/complaint tickets | As needed for dispute handling and compliance |
| Security logs | Shorter rolling windows unless needed for an investigation |
| Backups | Residual copies for a limited backup cycle |
When retention ends, we delete or anonymise data unless law requires otherwise. Registrar/registry escrow or thin-registry rules may require retention beyond our deletion of portal copies.
9. Security measures
We implement administrative, technical, and organisational measures appropriate to the risk, including: TLS encryption in transit; hashed passwords; role-based staff access; multi-factor authentication for staff where required; monitoring and logging; and vendor due diligence for key processors. No method of transmission or storage is completely secure. Report suspected incidents to [email protected] immediately.
10. Your rights
Subject to applicable law, you may request:
- Access to personal data we hold about you
- Correction of inaccurate data
- Deletion (subject to legal, tax, registrar, and abuse-retention limits)
- Restriction of certain processing
- Portability of data you provided, in a commonly used format where feasible
- Withdrawal of consent for consent-based processing
- Objection to certain legitimate-interest processing
Submit requests via client privacy tools where available or by email to [email protected]. We may verify your identity before acting. We will respond within a reasonable period and as required by law.
If you are in a jurisdiction with additional rights (for example GDPR-style rights in the EEA/UK), we will honour applicable rights for that jurisdiction to the extent they apply to our processing.
11. Children’s privacy
Services are intended for adults (18+). We do not knowingly collect personal data from children. If you believe a child has provided data, contact us and we will delete it where required.
12. Automated decision-making
We may use automated fraud and risk scoring at checkout or login. We do not intend to make solely automated decisions that produce legal or similarly significant effects without a path to human review where required by law.
13. Personal data breaches
If a personal-data breach is likely to result in a risk to your rights, we will investigate, contain the incident, and notify you and/or competent authorities as required by applicable law and our security runbooks.
14. Third-party websites
Our site may link to third-party sites. Their privacy practices are their own. Review their policies before providing data to them.
15. Changes to this Policy
We may update this Policy by posting a new version with a revised “Last updated” date. Material changes will be highlighted or notified when practicable. Continued use after the effective date constitutes acceptance where permitted; we will seek fresh consent where legally required.
16. Contact and complaints
Privacy questions and requests: [email protected]
Postal: address above
Service complaints: Complaints Policy
Bangladesh consumers may also escalate under the Consumer Rights Protection Act, 2009 to competent authorities.